ZeroHour

CVE-2016-3168

CVSS 3.0
6.4 medium
EPSS
2%p84
Published
()
Modified
Description

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."

Vendors
drupaldebian
Products
drupal, debian linux
Ecosystems
Drupal
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.